CVE-2023-28488: Buffer Overflow
client.c in gdhcp in ConnMan through 1.41 could be used by network-adjacent attackers (operating a crafted DHCP server) to cause a stack-based buffer overflow and denial of service, terminating the connman process.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-28488?
The severity of CVE-2023-28488 is high with a severity value of 7.
What is the affected software for CVE-2023-28488?
The affected software for CVE-2023-28488 includes ConnMan versions up to and including 1.41-2.
How can network-adjacent attackers exploit CVE-2023-28488?
Network-adjacent attackers can exploit CVE-2023-28488 by operating a crafted DHCP server to cause a stack-based buffer overflow and denial of service.
How can I fix CVE-2023-28488?
To fix CVE-2023-28488, you should update ConnMan to version 1.41-3 or apply the recommended patches provided by the software vendor.
Where can I find more information about CVE-2023-28488?
More information about CVE-2023-28488 can be found in the references provided: [Link 1], [Link 2], [Link 3].